D-Link DIR-823X
cpe:2.3:h:dlink:dir-823x:*:*:*:*:*:*:*, +1 more
- 250416
A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 firmware version. The issue arises in the 'uci_del' function within the '/goform/delete_prohibiting' file, where the 'delvalue' parameter is not properly validated. This lack of input validation allows attackers to manipulate the parameter and execute arbitrary commands on the device. The vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
To reproduce this vulnerability, log into the router and send a POST request to the '/goform/delete_prohibiting' endpoint. Include a crafted 'delvalue' parameter that exploits the input validation flaw in the 'uci_del' function. The injected command will be executed on the router's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.